2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-29875CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort...
CVE-2024-29874CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_nam...
CVE-2024-29873CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitna...
CVE-2024-29872CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. Th...
CVE-2024-29871CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/i...
CVE-2024-29870CRITICAL9.8SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business...
CVE-2024-29866CRITICAL9.1Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Or...
CVE-2024-29732CRITICAL9.8A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthent...
CVE-2024-27438CRITICAL9.8Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is n...
CVE-2024-1148CRITICAL9.8Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files...
CVE-2024-1147CRITICAL9.8Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.
CVE-2024-2161CRITICAL9.8Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects K...
CVE-2024-29864CRITICAL9.8Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.
CVE-2024-29859CRITICAL9.8In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file ...
CVE-2024-29858CRITICAL9.8In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid l...
CVE-2024-2054CRITICAL9.8The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users...
CVE-2024-2014CRITICAL9.8A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown cod...
CVE-2024-28123CRITICAL9.8Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the W...
CVE-2024-27922CRITICAL9.8TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure han...
CVE-2024-25239CRITICAL9.8SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL comm...
CVE-2024-1202CRITICAL9.8Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affe...
CVE-2024-29026CRITICAL9.1Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1...
CVE-2024-29037CRITICAL9.1datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Sta...
CVE-2024-29033CRITICAL9.1OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's ...
CVE-2024-25294CRITICAL9.1An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now